UBUNTU-CVE-2022-24122
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-24122
UBUNTU-CVE-2022-24122
Summary:
Details: kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
References: https://ubuntu.com/security/CVE-2022-24122, https://git.kernel.org/linus/f9d87929d451d3e649699d0f1d74f71f77ad38f5, https://www.openwall.com/lists/oss-security/2022/01/29/1, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f9d87929d451d3e649699d0f1d74f71f77ad38f5, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c54b245d011855ea91c5beff07f1db74143ce614, https://ubuntu.com/security/notices/USN-5278-1, https://www.cve.org/CVERecord?id=CVE-2022-24122
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
